Even if you practice good Cyber Fu, a ransomware attack can still happen. You'll instantly go from "confused stare at the screen" to "PANIC!"
Take a breath. Ransomware is bad...but you can take action against it. Do these 3 things when ransomware hits, and you can reduce the damage.
1. Isolate the computer from the rest of the network. Now.
Ransomware likes to spread from one computer to another. If you have it on your computer, you may be able to contain it there by acting fast.
- Disconnect the computer from the Internet. That includes shutting off Wi-Fi. On most computers there's a Wi-Fi Shutoff keyboard shortcut. It's marked with a symbol like this:
- Disconnect any external drives.
- Disconnect your webcam (if it's separate) or cover it (if it's built-in). Some ransomware will record you.
2. Do NOT turn the computer off.
Resist the urge to pull the plug! It's not always the best idea. Shutting down could remove files you may need, or hurt the computer's hardware. IT will need to examine the computer as-is anyway.
3. Notify your IT Department.
Call up your IT Department and tell them the situation. What you see on the screen, and what you've done in response. From there, it's up to them.
Your IT Department will try to clean the ransomware off first. If that doesn't work, they can restore from backup. You may lose some files in the process. Frustrating, but it could be much worse.
In medicine, there's the concept of "triage." Treating the most dangerous/life-threatening injury first, even if it means leaving a less-serious injury alone for a while.
These three actions, if taken on first suspicion of a ransomware attack, work as triage for your company network. At worst, you lose one computer...but you save everyone else's. As well as the company's critical data. That's good Cyber Fu.
Do you have a cybersecurity question you want answered? Send it in to firstname.lastname@example.org and it may show up in our next "Cyber Fu Tip."